gatling FTP Mode Directory Traversal Vulnerability
BID:56495
Info
gatling FTP Mode Directory Traversal Vulnerability
| Bugtraq ID: | 56495 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 02 2012 12:00AM |
| Updated: | Nov 02 2012 12:00AM |
| Credit: | Jann Horn |
| Vulnerable: |
gatling gatling 0 |
| Not Vulnerable: | |
Discussion
gatling FTP Mode Directory Traversal Vulnerability
gatling is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to retrieve arbitrary files in the context of the application.
Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Versions prior to gatling 0.13 are vulnerable.
gatling is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to retrieve arbitrary files in the context of the application.
Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks.
Versions prior to gatling 0.13 are vulnerable.
Exploit / POC
gatling FTP Mode Directory Traversal Vulnerability
Attackers can exploit this issue with a web browser or readily available tools.
Attackers can exploit this issue with a web browser or readily available tools.
Solution / Fix
gatling FTP Mode Directory Traversal Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.